¡¾Ç徲ͨ¸æ¡¿Î¢Èí4ÔÂÇå¾²¸üжà¸ö²úÆ·¸ßΣÎó²îͨ¸æ
2021-04-14
Ò». Îó²î¸ÅÊö
4ÔÂ14ÈÕ£¬Î¢ÈíÐû²¼4ÔÂÇå¾²¸üв¹¶¡£¬ÐÞ¸´ÁË114¸öÇå¾²Îó²î£¬Éæ¼°Windows¡¢Office¡¢Edge (Chromium-based) ¡¢Visual Studio Code¡¢Exchange Server¡¢Visual Studio¡¢AzureµÈÆÕ±éʹÓõIJúÆ·£¬ÆäÖаüÀ¨Ô¶³Ì´úÂëÖ´ÐкÍȨÏÞÌáÉýµÈ¸ßΣÎó²îÀàÐÍ¡£
±¾ÔÂ΢ÈíÔ¶ȸüÐÂÐÞ¸´µÄÎó²îÖУ¬ÑÏÖØË®Æ½ÎªÒªº¦£¨Critical£©µÄÎó²îÓÐ19¸ö£¬Ö÷Òª£¨Important£©Îó²îÓÐ88¸ö¡£ÇëÏà¹ØÓû§¾¡¿ì¸üв¹¶¡¾ÙÐзÀ»¤¡£ÏêϸÎó²îÁбíÇë²Î¿¼¸½Â¼¡£
²Î¿¼Á´½Ó£º
https://msrc.microsoft.com/update-guide/en-us/releaseNote/2021-Apr
¶þ. ÖØµãÎó²î¼òÊö
ƾ֤²úÆ·Ê¢ÐжȺÍÎó²îÖ÷ÒªÐÔɸѡ³ö´Ë´Î¸üÐÂÖаüÀ¨Ó°Ïì½Ï´óµÄÎó²î£¬ÇëÏà¹ØÓû§Öصã¾ÙÐйØ×¢£º
Exchange Server´úÂëÖ´ÐÐÎó²î£¨CVE-2021-28480/CVE-2021-28481/CVE-2021-28482/CVE-2021-28483£©£º
¹¥»÷Õß¿ÉʹÓÃÉÏÊöÎó²îÈÆ¹ýExchangeÉí·ÝÑéÖ¤£¬ÎÞÐèÓû§½»»¥¼´¿ÉʵÏÖÏÂÁîÖ´ÐС£ CVE-2021-28480ºÍCVE-2021-28481µÄCVSSÆÀ·ÖΪ9.8·Ö£¬ÊÇδÊÚȨԶ³Ì´úÂëÖ´ÐÐÎó²î£¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßʹÓÃÎó²î£¬¿ÉÔÚÄÚÍøµÄExchange·þÎñÆ÷¾ÙÐкáÏòÀ©É¢£¬¿ÉÄÜÔì³ÉÈ䳿¼¶Îó²îµÄΣº¦¡£
¹Ù·½Í¨¸æÁ´½Ó£º
https://msrc.microsoft.com/update-guide/en-US/security-guidance/advisory/CVE-2021-28480
https://msrc.microsoft.com/update-guide/en-US/security-guidance/advisory/CVE-2021-28481
https://msrc.microsoft.com/update-guide/en-US/security-guidance/advisory/CVE-2021-28482
https://msrc.microsoft.com/update-guide/en-US/security-guidance/advisory/CVE-2021-28483
Win32k ȨÏÞÌáÉýÎó²î£¨CVE-2021-28310£©£º
Win32k±£´æÈ¨ÏÞÌáÉýÎó²î£¬¹¥»÷ÕßʹÓôËÎó²î¿ÉÔÚÄ¿µÄÖ÷»úÉÏÒÔSYSTEMȨÏÞÖ´ÐÐí§Òâ´úÂë¡£ÏÖÔÚÎó²îϸ½ÚÒѹûÕæ£¬ÇÒÒѼì²âµ½ÔÚÒ°¹¥»÷¡£
¹Ù·½Í¨¸æÁ´½Ó£º
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-28310
Windows Hyper-V Çå¾²¹¦Ð§ÈƹýÎó²î£¨CVE-2021-28444£©£º
¹¥»÷Õß¿ÉÒÔÈÆ¹ýʹÓÃRouter GuardÉèÖõÄHyper-V£¬½«WindowsÉèÖÃΪÖÐÐÄÈË·ÓÉÆ÷£¬´Ó¶øÊµÏֽػñÁ÷Á¿²¢ÐÞ¸ÄÊý¾Ý°ü¡£
¹Ù·½Í¨¸æÁ´½Ó£º
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-28444
Windows SMBÐÅϢй¶Îó²î£¨CVE-2021-28324/CVE-2021-28325£©£º
Windows SMB±£´æÁ½¸öÐÅϢй¶Îó²î£¨CVE-2021-28324¡¢CVE-2021-28325£©£¬¹¥»÷Õß¿ÉÒÔ»á¼ûÄں˿ռäÖеÄÄÚ´æÄÚÈÝ¡£CVE-2021-28324ÎÞÐèÉí·ÝÑéÖ¤£¬¹¥»÷ÕßʹÓôËÎó²î¿ÉÒÔδÊÚȨ»ñȡĿµÄϵͳÃô¸ÐÐÅÏ¢¡£
¹Ù·½Í¨¸æÁ´½Ó£º
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-28324
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-28325
Èý. Ó°Ïì¹æÄ£
ÒÔÏÂÎªÖØµã¹Ø×¢Îó²îµÄÊÜÓ°Ïì²úÆ·°æ±¾£¬ÆäËûÎó²îÓ°Ïì²úÆ·¹æÄ£Çë²ÎÔĹٷ½Í¨¸æÁ´½Ó¡£
|
Îó²î±àºÅ |
ÊÜÓ°Ïì²úÆ·°æ±¾ |
|
CVE-2021-28480 CVE-2021-28481 CVE-2021-28482 CVE-2021-28483 |
Microsoft Exchange Server 2019 Cumulative Update 8 |
|
CVE-2021-28310 |
Windows Server, version 20H2 (Server Core Installation) Windows 10 Version 20H2 for ARM64-based Systems Windows 10 Version 20H2 for 32-bit Systems Windows 10 Version 20H2 for x64-based Systems Windows Server, version 2004 (Server Core installation) Windows 10 Version 2004 for x64-based Systems Windows 10 Version 2004 for ARM64-based Systems Windows 10 Version 2004 for 32-bit Systems Windows Server, version 1909 (Server Core installation) Windows 10 Version 1909 for ARM64-based Systems Windows 10 Version 1909 for x64-based Systems Windows 10 Version 1909 for 32-bit Systems Windows Server 2019 (Server Core installation) Windows Server 2019 Windows 10 Version 1809 for ARM64-based Systems Windows 10 Version 1809 for x64-based Systems Windows 10 Version 1809 for 32-bit Systems Windows 10 Version 1803 for x64-based Systems Windows 10 Version 1803 for 32-bit Systems |
|
CVE-2021-28444 |
Windows Server 2012 R2 (Server Core installation) Windows Server 2012 R2 Windows 8.1 for x64-based systems Windows Server 2016 (Server Core installation) Windows Server 2016 Windows 10 Version 1607 for x64-based Systems Windows 10 for x64-based Systems Windows Server, version 20H2 (Server Core Installation) Windows 10 Version 20H2 for x64-based Systems Windows Server, version 2004 (Server Core installation) Windows 10 Version 2004 for x64-based Systems Windows Server, version 1909 (Server Core installation) Windows 10 Version 1909 for x64-based Systems Windows Server 2019 (Server Core installation) Windows Server 2019 Windows 10 Version 1809 for x64-based Systems Windows 10 Version 1803 for x64-based Systems |
|
CVE-2021-28324 |
Windows Server, version 20H2 (Server Core Installation) Windows 10 Version 20H2 for ARM64-based Systems Windows 10 Version 20H2 for 32-bit Systems Windows 10 Version 20H2 for x64-based Systems Windows Server, version 2004 (Server Core installation) Windows 10 Version 2004 for x64-based Systems Windows 10 Version 2004 for ARM64-based Systems Windows 10 Version 2004 for 32-bit Systems |
|
CVE-2021-28325 |
Windows 10 Version 2004 for 32-bit Systems Windows Server, version 1909 (Server Core installation) Windows 10 Version 1909 for ARM64-based Systems Windows 10 Version 1909 for x64-based Systems Windows 10 Version 1909 for 32-bit Systems Windows Server 2019 (Server Core installation) Windows Server 2019 Windows 10 Version 1809 for ARM64-based Systems Windows 10 Version 1809 for x64-based Systems Windows 10 Version 1809 for 32-bit Systems Windows 10 Version 1803 for x64-based Systems Windows 10 Version 1803 for 32-bit Systems Windows 10 for 32-bit Systems Windows Server, version 20H2 (Server Core Installation) Windows 10 Version 20H2 for ARM64-based Systems Windows 10 Version 20H2 for 32-bit Systems Windows 10 Version 20H2 for x64-based Systems Windows Server, version 2004 (Server Core installation) Windows 10 Version 2004 for x64-based Systems Windows 10 Version 2004 for ARM64-based Systems Windows Server 2012 R2 (Server Core installation) Windows Server 2012 R2 Windows Server 2012 (Server Core installation) Windows Server 2012 Windows RT 8.1 Windows 8.1 for x64-based systems Windows 8.1 for 32-bit systems Windows Server 2016 (Server Core installation) Windows Server 2016 Windows 10 Version 1607 for x64-based Systems Windows 10 Version 1607 for 32-bit Systems Windows 10 for x64-based Systems |
|
|
|
|
|
|
ËÄ. Îó²î·À»¤
4.1 ²¹¶¡¸üÐÂ
ÏÖÔÚ΢Èí¹Ù·½ÒÑÕë¶ÔÊÜÖ§³ÖµÄ²úÆ·°æ±¾Ðû²¼ÁËÐÞ¸´ÒÔÉÏÎó²îµÄÇå¾²²¹¶¡£¬Ç¿ÁÒ½¨ÒéÊÜÓ°ÏìÓû§¾¡¿ì×°Öò¹¶¡¾ÙÐзÀ»¤£¬¹Ù·½ÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/en-us/releaseNote/2021-Apr
×¢£ºÓÉÓÚÍøÂçÎÊÌâ¡¢ÅÌËã»úÇéÐÎÎÊÌâµÈÔµ¹ÊÔÓÉ£¬Windows UpdateµÄ²¹¶¡¸üпÉÄÜ·ºÆðʧ°Ü¡£Óû§ÔÚ×°Öò¹¶¡ºó£¬Ó¦ÊµÊ±¼ì²é²¹¶¡ÊÇ·ñÀֳɸüС£
ÓÒ¼üµã»÷Windowsͼ±ê£¬Ñ¡Ôñ“ÉèÖÃ(N)”£¬Ñ¡Ôñ“¸üкÍÇå¾²”-“Windows¸üД£¬Éó²é¸ÃÒ³ÃæÉϵÄÌáÐÑÐÅÏ¢£¬Ò²¿Éµã»÷“Éó²é¸üÐÂÀúÊ·¼Í¼”Éó²éÀúÊ·¸üÐÂÇéÐΡ£
Õë¶ÔδÀÖ³É×°ÖõĸüУ¬¿Éµã»÷¸üÐÂÃû³ÆÌø×ªµ½Î¢Èí¹Ù·½ÏÂÔØÒ³Ãæ£¬½¨ÒéÓû§µã»÷¸ÃÒ³ÃæÉϵÄÁ´½Ó£¬×ªµ½“Microsoft¸üÐÂĿ¼”ÍøÕ¾ÏÂÔØ×ÔÁ¦³ÌÐò°ü²¢×°Öá£

AG¹«Ë¾ÔÆ







